> Markdown version of [/jobs/ext/2433886-cloud-security](https://www.wearedevelopers.com/jobs/ext/2433886-cloud-security). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cloud Security - **Company:** Conimurrr - **Location:** Berlin, Germany - **Experience:** Expert - **Salary:** €60,000.0 - €100,000.0 - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Amazon Web Services, Software System Penetration Testing, Cloud Computing Security, Identity and Access Management, Information Security Management, Systems Development Life Cycle, Software Vulnerability Management, Data Logging, Google Cloud, Large Language Models, Terraform, Devsecops - **Published:** August 12, 2026 - **Apply:** https://de.indeed.com/viewjob?jk=3a71cb9a35b146e3 ## About the Role Must-Haves: * Hands-on cloud security (AWS or GCP) incl. Terraform IaC * End-to-end ownership of ISO27001 or C5 certification & audits * DevSecOps, secure SDLC, threat modeling, vulnerability management experience * German & English - full professional fluency * 5+ years in similar security/compliance roles Nice-to-Haves: * Healthcare / highly sensitive data environments * Medical Device Regulation exposure (MDR, IEC 62304) * AI/LLM security design experience Dealbreakers / Red Flags: * Policy-only background with no hands-on technical work * Lacking audit ownership experience (ISO/C5/SOC2) * Cannot work on-site in Berlin when required Personality Traits: * Reliable * Autonomous * Conscientious, * Experience: Minimum 5 years in IT security & compliance with audit ownership * Education: Bachelor's degree required (field not specified) * Specific Tools/Technologies: AWS, GCP, Terraform, logging/monitoring stacks, Vanta (for compliance evidence) ## Description * Own security & compliance end-to-end (cloud, product, internal IT) * Harden AWS/GCP environments: IAM, networking, encryption, logging, monitoring, detection * Embed DevSecOps into SDLC: threat modeling & vulnerability management with engineers * Maintain & improve ISO 27001 and C5 certifications; lead audits and corrective actions * Manage external security work: penetration tests, security reviews, vendor assessments * Design & enforce internal IT baseline: identity, MDM, device policies, access model, on/off-boarding * Provide security training and guidance across the organization ## Related Videos - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Infrastructure as Code: The Developer's Secret Weapon](https://www.wearedevelopers.com/videos/1221-infrastructure-as-code-the-developer-s-secret-weapon) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [Crypto-secure Data Management with In-Database Blockchain](https://www.wearedevelopers.com/videos/632-crypto-secure-data-management-with-in-database-blockchain) - [DevSecOps: Security in DevOps](https://www.wearedevelopers.com/videos/36-devsecops-security-in-devops) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) ## Related Articles - [The Biggest German Tech Companies](https://www.wearedevelopers.com/magazine/424-the-biggest-german-tech-companies) - [Finding Jobs in Germany](https://www.wearedevelopers.com/magazine/375-finding-jobs-in-germany) - [Where to Find German Tech Jobs](https://www.wearedevelopers.com/magazine/366-where-to-find-german-tech-jobs) - [How to Find Tech Jobs in Berlin](https://www.wearedevelopers.com/magazine/291-how-to-find-tech-jobs-in-berlin) - [How to Land a Developer Job in Berlin](https://www.wearedevelopers.com/magazine/1-how-to-land-a-developer-job-in-berlin) - [Best Coding Boot Camps in Germany](https://www.wearedevelopers.com/magazine/237-best-coding-boot-camps-in-germany)